Junglewise Threat Intelligence

CVE-2026-86205: h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative

CVE-2026-86205 · Severity: medium · CVSS 5.4 · Published 2026-09-06

Technologies: h3 (npm). Vendors: npm.

Executive brief

H3 is a popular HTTP framework used to build web applications and APIs. The redirectBack() function, which safely redirects users back to their referrer after form submission, contains a flaw that allows attackers to redirect users to external phishing sites by crafting malicious URLs. This can lead to credential theft and compromise of user accounts through phishing attacks.

Technical details

The vulnerability is an open redirect (CWE-601) in the redirectBack() utility function located in src/utils/response.ts. The function validates that a Referer header shares the same origin as the current request before using its pathname for the Location header. However, it fails to sanitize protocol-relative paths (starting with //). An attacker can craft a URL like http://target.com//evil.com/path that passes the origin check (since the origin is target.com) but extracts a pathname of //evil.com/path, which browsers interpret as a protocol-relative redirect to an external domain. The vulnerability requires user interaction (the user must follow an attacker-crafted link and then trigger a redirectBack() call), is network-accessible, and requires no authentication. A fix is available in version 2.0.1-rc.18 and later, which sanitizes the pathname to prevent protocol-relative paths.

Affected products

  • H3 H3 2.0.1-rc.17

Timeline

  • 2026-03-23: disclosed
  • 2026-03-23: patched: Fixed in version 2.0.1-rc.18

References

Related threats